Built for authorized security testing

Find the signal.
Skip the noise.

SpyHunt brings reconnaissance, web security testing, and repeatable workflows into one focused platform for pentesters, bug bounty hunters, and security teams.

Community edition available Pro subscription for serious operators

SpyHunt Pro overview showing 55 security modules across six categories Real product interface Explore →
55integrated modules
Oneoperator-focused workflow
Lesstool switching and noise

SpyHunt by Gotroot Labs

A unified recon and web security toolkit — from subdomain discovery to vulnerability scanning, all in one operator-focused interface.

spyhunt / pro

Recon to exploit, one workflow

SpyHunt PRO combines OSINT, active scanning, and chain-based workflows so you spend less time switching tools and more time finding real issues.

  • Subdomain enumeration, DNS, and asset discovery
  • HTTP probing, directory brute-force, and endpoint mapping
  • XSS, SQLi, CRLF, request smuggling, and more
  • WordPress audits, JWT analysis, and cloud misconfig checks
  • Chain workflow — pipe results between modules automatically
  • Built-in browser panel for live target inspection
SpyHunt Pro dashboard with project metrics, reports, and scan activity Engagement dashboard View tour →

Everything you need on one target

Modular scanners designed for accuracy — fewer false positives, smarter baselines, and workflows that match how operators actually work.

Asset discovery

Subdomains, DNS records, certificate transparency, and live host detection across large scopes.

Web recon

HTTP probing, technology fingerprinting, JS endpoint extraction, and directory enumeration.

Vulnerability scanning

XSS, SQL injection, CRLF, open redirects, CORS, SSRF, and request smuggling probes.

CMS & APIs

WordPress audits with CVE lookup, JWT analysis, GraphQL introspection, and API mapping.

Chain workflow

Pipe output from one module to the next — recon flows into probing, then into vuln scans.

Cloud & infra

AWS and Azure misconfiguration checks, S3 bucket discovery, and favicon-based tech ID.

Built by operators, for operators

Gotroot Labs is an offensive security software company focused on building tools that respect your time. We ship software shaped by real bug bounty and penetration testing workflows — not checkbox scanners that flood you with noise.

Our flagship product, SpyHunt, started as a personal recon toolkit and evolved into a full platform with dozens of integrated modules, chain automation, and a professional GUI built for long engagement sessions.

SpyHunt Community will remain free and open source. SpyHunt Pro adds advanced modules, higher limits, chain workflows, and priority updates for professionals who rely on these tools every day.

01

Signal over noise

Smart baselines and context-aware detection to cut false positives.

02

Speed at scale

Multi-threaded scanning with rate limiting that respects target stability.

03

Responsible tooling

Built for authorized security testing. Use only on systems you own or have permission to test.

Ready to work faster?

Get in touch about a SpyHunt Pro subscription, team access, Community installers, partnerships, or security research.

contact@gotrootlabs.com
Talk to us about Pro